Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK

Security experts have warned of a new campaign, dubbed 'Mach-O Man,' which enables the Lazarus Group to transform ordinary business interactions into a conduit for credential theft and data loss. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group is targeting high-value executives and firms in the fintech and cryptocurrency sectors, with estimated cumulative loot of $6.7 billion since 2017. In recent weeks, the hackers have stolen over $500 million from the Drift and KelpDAO exploits, demonstrating a sustained and well-funded campaign. The Mach-O Man attack utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs a social engineering technique known as ClickFix to trick victims into providing access to corporate systems and financial resources. The attack involves sending executives fake meeting invites, leading them to a convincing website that instructs them to paste a command into their terminal to 'fix a connection issue,' thereby granting immediate access to sensitive information. With its high activity level and state-directed financial operations, the Lazarus Group poses a significant threat to the crypto industry, which should view it as a constant and well-funded menace rather than just a news headline.